Digi International PortServer TS, Digi One SP IA
Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices contain authentication bypass vulnerabilities (CWE-863) and stored cross-site scripting flaws (CWE-79) in their web interfaces. Successful exploitation allows attackers to bypass authentication restrictions, access configuration resources without proper credentials, extract stored credentials, and inject malicious scripts that execute when authorized users access the interface. The vulnerabilities are rooted in insufficient access controls and inadequate input validation on the web application.
- Network access to the web interface (HTTP port 80)
- No authentication bypass required for initial access to certain resources
- User interaction required for stored script injection attacks (XSS)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/08f86574-2657-4449-ad67-d2a29647e70eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.